Payload Vending Machine
A massive collection of copy-paste payloads for SQLi, XSS, RCE, and more.
Generic Auth Bypass
Classic tautology bypass
Admin Auth Bypass
String based tautology
Username Auth Bypass
Comment out password check
Auth Bypass (Hash)
MySQL comment style
Auth Bypass (Union)
Union based login bypass
Union Select Test
Test column count (3)
Union Select Version
Get DB version (MSSQL/MySQL)
Union Select User
Get current user
Union Select Tables
List tables (MySQL)
Error Based (Convert)
MSSQL conversion error
Time Based (Sleep)
MSSQL 5 second delay
Time Based (Sleep MySQL)
MySQL 5 second delay
Time Based (PG Sleep)
PostgreSQL 5 second delay
Blind Boolean True
Should return normal page
Blind Boolean False
Should return missing content
SQLi Polyglot
Try to sleep in multiple contexts
Basic Alert
Classic script tag
Basic Prompt
Prompt dialog
Image OnError
Image tag error handler
SVG OnLoad
SVG load handler
Body OnLoad
Body load handler
XSS Polyglot
Breaks out of many contexts
XSS Polyglot Short
Break attribute and script
Attribute Break
Break out of attribute
Protocol Handler
URL protocol
AngularJS Template
Angular sandbox escape
VueJS Template
Vue sandbox escape
Unix List Files
Semicolon separator
Unix ID
Backtick execution
Unix Pipe
Pipe to command
Unix Background
Background execution
Windows Dir
Windows separator
Windows IPConfig
OR operator
Blind Sleep (Unix)
Execution delay
Blind Ping
Ping delay
Netcat Reverse Shell
Classic nc reverse shell
Bash Reverse Shell
Bash TCP reverse shell
Etc Passwd
Standard traversal
Null Byte
Null byte bypass
Double Encoding
URL double encoding
Windows Boot.ini
Windows boot config
Windows Win.ini
Windows config
PHP Filter Base64
Read source code
PHP Input
Execute POST data
Data URI
Inline execution
Jinja2 Basic
Basic math test
Jinja2 Config
Dump config
Jinja2 RCE
Python RCE (index varies)
Twig Basic
Basic math test
Twig RCE
Twig RCE
Java Basic
EL expression
Spring RCE
Spring SpEL RCE
XXE File Read
Basic file read
XXE SSRF
Internal network probe
Blind XXE OOB
Out of band exfiltration
Billion Laughs
DoS Attack
LDAP Bypass
Wildcard bypass
LDAP Admin
Logic bypass
XPath Bypass
XPath injection
Format String
Leak stack memory